Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
AI Security Startup Alice Raises $140M Amid Surging Enterprise AI Threats
August 25, 2026
SynkLoader Malware Impersonates IT Support on Microsoft Teams
August 25, 2026
AI Agents Breach Government Systems, Steal 2,500 Records
August 25, 2026
Home/Threats/SynkLoader Malware Impersonates IT Support on Microsoft Teams
Threats

SynkLoader Malware Impersonates IT Support on Microsoft Teams

Key Takeaways A new malware campaign, SynkLoader, is exploiting Microsoft Teams to deliver malicious payloads. Attackers impersonate IT support personnel through Teams messages and vishing calls. The...

Sarah simpson
Sarah simpson
August 25, 2026 3 Min Read
2 0

Key Takeaways

  • A new malware campaign, SynkLoader, is exploiting Microsoft Teams to deliver malicious payloads.
  • Attackers impersonate IT support personnel through Teams messages and vishing calls.
  • The campaign tricks users into downloading a fake “PowerShell Cleaner” MSI installer from legitimate Azure Blob Storage.
  • SynkLoader uses a hash-gated PowerShell loader and a Python backdoor with dynamic C2 capabilities, making detection challenging.
  • This attack highlights the increasing threat of social engineering combined with obfuscated malware delivery on trusted internal platforms.

A sophisticated malware campaign leveraging Microsoft Teams is actively distributing a new PowerShell loader dubbed SynkLoader. Threat actors are impersonating internal IT support staff to trick employees into downloading and executing malicious software, transforming routine support interactions into a vector for compromise.

Table Of Content

  • Key Takeaways
  • SynkLoader Mimics IT Support Personnel
  • Loader Hides Its Next Stage

This campaign bypasses traditional security measures by focusing on social engineering rather than exploiting software vulnerabilities. It places the decision to install a seemingly legitimate “fix” directly into the hands of unsuspecting employees.

Attackers initiate contact through Microsoft Teams messages and voice phishing (vishing) calls, posing as IT support personnel. They then persuade victims to download a fraudulent MSI installer, deceptively named “PowerShell Cleaner,” thereby integrating a familiar workplace communication channel into their attack chain.

Analysts at ReliaQuest Threat Research have identified SynkLoader as a hash-gated PowerShell loader. The malware is particularly notable for its combination of a highly convincing social engineering approach with code designed to evade detection by researchers and automated analysis tools, as detailed in a report. The ReliaQuest Threat Research team emphasized that this operation can evade security controls primarily focused on email attachments or overtly malicious websites.

By utilizing legitimate Azure Blob Storage for malware delivery and executing critical components directly in memory, SynkLoader makes the malicious download appear less suspicious while significantly reducing forensic traces for defenders.

SynkLoader Mimics IT Support Personnel

The attack commences with a message or call seemingly originating from an internal IT department member. The attacker offers assistance, often presenting the installer as a system cleaner or repair utility. This tactic mirrors other Teams helpdesk impersonation attacks that exploit familiar support language to build trust with victims.

Victims are then directed to download an MSI file hosted on Azure Blob Storage. While cloud hosting itself is not inherently malicious, its use can lend an air of legitimacy to the download, making it less likely to be questioned by the target. The August 24, 2026 tweet from ReliaQuest Threat Research highlights the ongoing nature of this threat.

Upon execution, the deceptive installer launches the SynkLoader, initiating the subsequent stages of the attack without relying on traditional email attachments. This delivery mechanism, whether via vishing or Teams messages, consistently leads to the same malicious installer. This pattern is crucial because employees, often trained to scrutinize email links, may perceive Teams as a secure and trusted communication environment. Recent incidents, such as those involving brief support-themed Teams calls, demonstrate how quickly attackers can establish an entry point by creating urgency and offering a seemingly simple solution.

Loader Hides Its Next Stage

Once installed, SynkLoader decrypts its payload in memory and performs a cryptographic hash check before execution. Should the payload be altered or improperly extracted, the loader quietly terminates. This mechanism can significantly hinder automated analysis, as a sandbox environment might never witness the full infection sequence.

Following this, the loader deploys a Python backdoor that dynamically retrieves its functionalities from command-and-control (C2) infrastructure as needed. By keeping these capabilities external to the initial file, attackers limit the information obtainable from static analysis. Furthermore, the backdoor may appear dormant if its C2 servers are offline or inaccessible during analysis, further complicating detection. This approach underscores the broader trend of abusing scripting tools in attacks, where PowerShell evasion techniques have enabled criminals to execute code with minimal visible files, making unusual script activity a critical indicator of compromise rather than harmless maintenance.

This design also creates an investigative challenge. An analyst might dismiss a file as incomplete or benign if they cannot reproduce the precise execution conditions. Therefore, incident response teams must preserve the installer, meticulously review process and network logs, and actively search for related activity, rather than prematurely closing an alert after a single failed execution. The prevalence of similar <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/4a75a0d3-b272-486b-a5c0-449da2559774/SynkLoader-mimic-as-IT-support-personnel-Attacking-Users-Via-Microsoft-Teams.pdf?AWSAccess

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwarephishingSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

AI Agents Breach Government Systems, Steal 2,500 Records

Next Post

AI Security Startup Alice Raises $140M Amid Surging Enterprise AI Threats

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
ToxNetV2 Linux Botnet Leverages NVIDIA AI to Automate Attacks
August 25, 2026
Fake Microsoft Security Scan Tricks Users into Removing Antivirus
August 25, 2026
Microsoft August 2023 Update Breaks PDF/XPS Generation
August 25, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us